跳转到帖子

Red Hat OpenShift: CVE-2023-45288: golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

recommended_posts

发布于
  • Members

Red Hat OpenShift: CVE-2023-45288: golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
04/04/2024
Created
04/29/2024
Added
04/29/2024
Modified
02/10/2025

Description

An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.

Solution(s)

  • linuxrpm-upgrade-microshift
  • linuxrpm-upgrade-openshift

References

  • https://attackerkb.com/topics/cve-2023-45288
  • CVE - 2023-45288
  • RHSA-2024:1616
  • RHSA-2024:1668
  • RHSA-2024:1679
  • RHSA-2024:1681
  • RHSA-2024:1683
  • RHSA-2024:1892
  • RHSA-2024:1897
  • RHSA-2024:1899
  • RHSA-2024:1962
  • RHSA-2024:1963
  • RHSA-2024:2049
  • RHSA-2024:2060
  • RHSA-2024:2062
  • RHSA-2024:2068
  • RHSA-2024:2079
  • RHSA-2024:2088
  • RHSA-2024:2562
  • RHSA-2024:2625
  • RHSA-2024:2664
  • RHSA-2024:2667
  • RHSA-2024:2668
  • RHSA-2024:2671
  • RHSA-2024:2672
  • RHSA-2024:2699
  • RHSA-2024:2724
  • RHSA-2024:2728
  • RHSA-2024:2729
  • RHSA-2024:2773
  • RHSA-2024:2782
  • RHSA-2024:2865
  • RHSA-2024:2875
  • RHSA-2024:2892
  • RHSA-2024:2901
  • RHSA-2024:2929
  • RHSA-2024:2930
  • RHSA-2024:2932
  • RHSA-2024:2933
  • RHSA-2024:2935
  • RHSA-2024:2936
  • RHSA-2024:2941
  • RHSA-2024:3259
  • RHSA-2024:3314
  • RHSA-2024:3315
  • RHSA-2024:3316
  • RHSA-2024:3327
  • RHSA-2024:3331
  • RHSA-2024:3346
  • RHSA-2024:3352
  • RHSA-2024:3467
  • RHSA-2024:3479
  • RHSA-2024:3523
  • RHSA-2024:3621
  • RHSA-2024:3637
  • RHSA-2024:3680
  • RHSA-2024:3781
  • RHSA-2024:3885
  • RHSA-2024:3889
  • RHSA-2024:4006
  • RHSA-2024:4010
  • RHSA-2024:4023
  • RHSA-2024:4034
  • RHSA-2024:4041
  • RHSA-2024:4125
  • RHSA-2024:4146
  • RHSA-2024:4464
  • RHSA-2024:4484
  • RHSA-2024:4543
  • RHSA-2024:4545
  • RHSA-2024:4546
  • RHSA-2024:4631
  • RHSA-2024:4677
  • RHSA-2024:4699
  • RHSA-2024:4922
  • RHSA-2024:4933
  • RHSA-2024:4934
  • RHSA-2024:4960
  • RHSA-2024:4982
  • RHSA-2024:5013
  • RHSA-2024:6004
  • RHSA-2024:6009
  • RHSA-2024:6221
  • RHSA-2024:6406
  • RHSA-2024:6642
  • RHSA-2024:6811
  • RHSA-2024:7164
  • RHSA-2024:8235
  • RHSA-2024:8425
  • RHSA-2024:8688
  • RHSA-2024:8692
  • RHSA-2025:0536
  • RHSA-2025:0832
View more
  • 查看数 706
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…